
Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.
; &
;; ;&
;;; ;;;
; ;;; ;;; ;
;;; ;;; ; ;; ;;; ;;;
;;;; ;;;; ;;; && ;;; ;;;; ;;;;
;;;; ;;;; ;;;;;;;;;; ;;;; ;;;;
;;;;;;;;; ;;;;;;;;;;;;;;;; ;;;;;;;;;
&;;;;;;;;;;;;$x;;;;;;;;;;;;
;;;;;;;;;;&&&+++&&&;;;;;;;;;;;
;;;;;;;;; ;;;&&+&&&&&+&&;;; ;;;;;;;;;;
;;;& ;; ;;;&+&&&&&&&+&&;;; ;; &;;;
;;; ;;;; ;;;&&+&&&&&&+&;;; ;;;; ;;;
;;; ;;; ;;;;&&++&++++&&;; ;;; ;;;
;; ;;; ;;;;;;;;;;;&&&&; ;;; ;;
;; ;;; ;;;;;;;;;;;;;; ;;; ;;
; ;;; ;;;;;;;;;; ;;; ;
&;; ;;;; ;;&
;; ;; ;;;
; ;
Attack Surface Intelligence Engine — Terminal Edition
Built by QYVORA OffSec — Tamale, Ghana
anansi target.com anansi scan target.com anansi target.com --verbose anansi target.com --deep anansi target.com -o json > results.json anansi target.com --modules discovery,tls,takeover
Only scan targets you own or have explicit written permission to test.
ANANSI CLI is a terminal-first attack surface recon tool for pentesters and bug bounty hunters. Give it a domain — it runs a full ten-phase intelligence and exploitation pipeline and prints raw technical output you can act on immediately.
By default, ANANSI filters out the noise and only displays found assets (e.g., live subdomains, active HTTP/HTTPS hosts, successful TLS certificates, missing security headers on live URLs, exposed paths, and confirmed takeovers). This keeps your terminal clean. If you want to see all attempted checks, including dead subdomains, failed connections, and unchecked endpoints, simply enable the verbose flag (-v/--verbose).
| Phase | Module | What it finds |
|---|---|---|
| 01 | DISCOVERY | Subdomains via crt.sh CT logs + DNS brute-force wordlist |
| 02 | PROBE | Live HTTP/HTTPS hosts — status codes, servers, redirect chains, titles |
| 03 | TLS | Certificate expiry, SANs, protocol version, cipher, self-signed detection |
| 04 | HEADERS | Missing security headers, CORS misconfigurations |
| 05 | PATHS | Exposed files — .env, .git, configs, admin panels, backups, API docs |
| 06 | TECH-STACK | Deep audit of detected platforms — version detection, WordPress plugins/themes, XML-RPC, user enumeration, config backups, known-vulnerable version matching |
| 07 | TAKEOVER | Dangling CNAMEs pointing to unclaimed cloud services |
| 08 | OSINT | Emails, phone numbers, employees, WHOIS registrant data |
| 09 | CHAIN | Assembles findings into multi-step exploit paths (low → high → critical) with per-step exploitation techniques |
| 10 | EXPLOIT | Actively proves exploitable findings against the authorized target with live HTTP request/response evidence |
cgo-blocked system lookups using pure Go goroutines.--threads, jobs pulled from a channel). No goroutine-per-job churn — even an 8,000+ rule path sweep stays at stable concurrency.robots.txt Allow/Disallow entries are turned into extra path probes, surfacing intentionally-hidden directories for one extra request per host.When a host is fingerprinted as WordPress, Drupal, Joomla, Magento, Ghost, Moodle, MediaWiki, Laravel, or another platform, ANANSI descends that stack instead of stopping at the surface: